- Had this happened to any solo person, they'd surely be thrown in jail immediately with a heavy bond. Rules are for poor people.
- They aren't getting prosecuted because everyone involved has made nice and turned it into a marketing exercise.
I heard about it on the radio (local Johannesburg radio station) before I saw it on HN. The economist had a full article up about it before the end of the day, and in the evening Sky news had talking heads up chatting about what it all meant while clearly being clueless.
Someone spent a LOT of money to turn this into a PR exercise for both companies. We'll never hear the entire story about what happened but I'm sure there was a lot of handshaking going on behind the scenes.
by boveyking
1 subcomments
- There is a legal gap. The main law people look at is the Computer Fraud and Abuse Act (CFAA), plus state computer-crime laws, contract terms, and general civil claims.
However, LLM active attacks do not always fit neatly into existing hacking laws, because the system may be accessed through normal text prompts rather than by breaking into a classic computer boundary. That is why legal commentators say the U.S. still lacks a clean, specific rule for adversarial AI/LLM testing and attacks.
In order to prosecuted, there must be prosecutor or complainant to sue, but in this case, it is so complicate due to the legal gap.
by andyjohnson0
0 subcomment
- Perhaps none of the organisations involved want a court to be setting precidents on the actions of ai models?
Also, what other people have said about it being turned into a (mutually beneficial?) marketing opportunity.
- That's an interesting point. I found the narrative - or at least what and how it was closed - interesting.
The questions is all about the responsibility and accountability. Is there a clear legislation about who is responsible for the actions of the AI model in the US?
My assumption is no (but I am no expert in US law with regards to this). It would in any case become a very expensive law suite.
- It's surreal that we (media, govt, public, AI companies) are in awe of how dangerous a model can be how much it can misbehave. We seem to be measuring AI on how much harm it can do rather than how much good it can do.
by saidnooneever
1 subcomments
- it might be possible to report it as an incident but not as a crime. unsure about France but i can imagine there is a distinction.
depending then on openai response and hugging faces reported severity/damages etc it could go further to a settlement or court.
since in France i think u cannot sue like in the US, it might not be appealing to pursue further legal action due to involved costs/time.
Also its unlikely an engineer would get penalty unless it can be proven they did it with malicious intent. If its an operational mistake afaik if there is no huge damage or human cost (injury or worse) then it would be a business / executives thing not a workerbee problem
by abdelrahman_d
1 subcomments
- I feel like OpenAI fabricated a fake news story to be like Anthropic when they said Mythos was very powerful and had hacked things too.
- successful prosecution would require intent to cause damage and causation of real damage.
what happened could be negligence if it caused unintentional damage, or what amounts to tortious interference, however that probably requires knowledge of possible damages.
by FrankWilhoit
1 subcomments
- Just as there is "too big to fail", there is "too big to prosecute".
by ChrisArchitect
0 subcomment
- More discussion: https://news.ycombinator.com/item?id=48997548
- [dead]
by aleenz1102
0 subcomment
- [flagged]
by mandarinclips
0 subcomment
- [dead]
by TesterVetter
0 subcomment
- [dead]
- your assuming (incorrectly) this actually happened